We know the audit from the inside
Secuvise handles product cybersecurity for machine builders and device manufacturers. From the development process through the architecture to the evidence an auditor accepts.
Why Secuvise exists
Secuvise started in 2024, and the project history behind the team goes back a lot further. The idea for it came from the certification side of the table. Part of our team has worked at testing and certification bodies, TÜV among them, and in the cybersecurity practice of a large audit firm: IEC 62443 certifications, setting up new testing services and labs, EN 18031, penetration testing on behalf of certification bodies.
Sit in that seat for a while and the same picture keeps coming back. Security requirements that never made it into the development process. Ownership left floating between development, product management and quality. Threat models put together once, shortly before the audit. Evidence pulled together at the last minute.
An auditor can name the gaps. Closing them is off limits, because independence rules say so. The consulting arm of an audit firm runs into the same line: it cannot freely advise a company the firm also audits.
So the problem stayed with the manufacturers. What they need is someone who knows how an assessment works and still does the hands-on work on processes, methods and engineering. That is what Secuvise is for.
Products only
No ISMS programs, no corporate IT, no functional safety. Your machine sits in the field for a decade or more, is connected for remote maintenance and is maintained by your own team. An office laptop plays by different rules.
Both sides of the audit
We know what an auditor wants to see before they ask for it, and which wording in an assessment invites a follow-up question.
Regulation and engineering in one place
Scope the requirement, set the architecture, implement crypto and secure boot, write the evidence. Nothing gets lost in handovers between separate suppliers.
Fixed prices for defined deliverables
The people on your project have done the job before. No learning curve on your invoice.
Consulting is usually billed by the hour. The effort stays open-ended, the risk sits with you, and the longer it runs, the better it works out for the consultant. We do it the other way around: you buy a deliverable. Gap analysis, SDLC description, threat model, test report, conformity evidence. In most cases the proposal names a fixed price, with no risk premium for uncertainty we do not have, because we know from earlier projects how long the work takes.
And we are not starting from a blank page. For development processes, risk assessments, PSIRT and evidence documents we bring templates that already cover the requirements. That saves you the weeks that otherwise go into building them.
What our clients say
Secuvise has always supported us closely and reliably in developing our security concepts. The collaboration has been consistently constructive and collegial, exceeding our expectations. I look forward to continued partnership across all areas of cybersecurity.
We faced the challenge of bringing our entire mobile robot portfolio into EN 18031 compliance under significant time pressure. Secuvise did not just provide advice, but actively supported us hands-on – from structured information gathering and gap analysis through to executing conformity testing. Without this pragmatic support, we would not have met our deadline.
For regulatory compliance of our products, we needed a partner who combines technical depth with practical implementability. Working with Secuvise was straightforward, and their solutions integrated well into our development process.
Where our team comes from
We come from testing and from engineering: certification bodies, machine and device manufacturing, firmware and software development, security testing.
That mix decides how we work. A requirement counts as translated once your development team can build from it, and a threat model is finished once a developer can make a decision from it. A process nobody follows shows up in the audit. On the evidence, we know what the auditor will look for, because some of us used to do the assessing.
How we work
Where we come in depends on how far along you are.
Map where you stand
We determine which requirements apply to your product and where the gaps are. You get a prioritized roadmap with effort estimates.
Put the processes in place
We build the development process, risk assessment, vulnerability handling and PSIRT into the way your teams already work, so the evidence is produced along the way.
Take work off your desk
Threat model, security architecture, test support, evidence documents: we take on individual packages alongside your developers.
Get in touch
Find out where your product stands
Thirty minutes to pin down which requirements apply to your products, which deadlines affect you and where the biggest risk sits. EN 18031 has applied since August 2025, the CRA from December 11, 2027. You come away knowing what to do next.
Book a 30-minute call
Fill in the form and we will get back to you shortly to set up a time.